Missing Authentication for Critical Function in ActiveMQ Artemis and Artemis - CVE-2026-27446
Published: March 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication.
The vulnerability exists due to missing authentication checks within the Core protocol. A remote non-authenticated attacker can use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker and inject messages into any queue and/or exfiltrate messages from any queue via the rogue broker.
Affected software
Artemis
AMQ Broker
How to mitigate CVE-2026-27446
AMQ Broker - addressed in versions 7.12.6, 7.13.4